Show filters
733 Total Results
Displaying 291-300 of 733
Sort by:
Attacker Value
Unknown

CVE-2020-5511

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
Attacker Value
Unknown

CVE-2019-19950

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Attacker Value
Unknown

CVE-2019-19953

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Attacker Value
Unknown

CVE-2019-19951

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Attacker Value
Unknown

CVE-2016-1000229

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
swagger-ui has XSS in key names
Attacker Value
Unknown

CVE-2011-4310

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
Attacker Value
Unknown

CVE-2011-1028

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Attacker Value
Unknown

CVE-2019-17629

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
Attacker Value
Unknown

CVE-2019-17630

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
Attacker Value
Unknown

CVE-2015-9492

Disclosure Date: October 11, 2019 (last updated November 27, 2024)
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.